2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-25729HIGH7.5An information disclosure vulnerability in Bosscomm IF740 Firmware versions:11001.7078 & v11001.0000 and System versions...
CVE-2025-25477HIGH8.1A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary do...
CVE-2025-1687HIGH8.8The Cardealer theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.4. T...
CVE-2025-1682HIGH8.8The Cardealer theme for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.6.4 due to m...
CVE-2025-26264HIGH8.8GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerabili...
CVE-2025-21815HIGH7.1In the Linux kernel, the following vulnerability has been resolved: mm/compaction: fix UBSAN shift-out-of-bounds warnin...
CVE-2025-21812HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ax25: rcu protect dev->ax25_ptr syzbot found a loc...
CVE-2025-21811HIGH7.8In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect access to buffers with no active re...
CVE-2025-21800HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix definer's HWS_SET32 macro for ne...
CVE-2025-23687HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simonhunter Woo St...
CVE-2025-25333HIGH7.5An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.
CVE-2025-1756HIGH7.8mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized acti...
CVE-2025-1755HIGH7.8MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthori...
CVE-2025-25761HIGH7.2HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the component Appcenter.php.
CVE-2025-25760HIGH7.5A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access inter...
CVE-2025-25759HIGH7.5An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitra...
CVE-2025-22280HIGH7.6Missing Authorization vulnerability in revmakx DefendWP Firewall defend-wp-firewall allows Exploiting Incorrectly Config...
CVE-2025-1739HIGH7.1An Authentication Bypass vulnerability has been found in Trivision Camera NC227WF v5.8.0 from TrivisionSecurity. This vu...
CVE-2025-1692HIGH8.8The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboa...
CVE-2025-1282HIGH8.8The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due ...
CVE-2025-1717HIGH8.1The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. Th...
CVE-2025-1295HIGH8.8The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, an...
CVE-2025-21797HIGH7.8In the Linux kernel, the following vulnerability has been resolved: HID: corsair-void: Add missing delayed work cancel ...
CVE-2025-21794HIGH7.1In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix stack-out-of-bounds read...
CVE-2025-21791HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vrf: use RCU protection in l3mdev_l3_out() l3mdev_...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now